CVE-2026-86198
Deferred Deferred - Pending Action

PocketMine-MP ResourcePackClientResponsePacket Memory Exhaustion

Vulnerability report for CVE-2026-86198, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-10

Assigner: VulnCheck

Description

PocketMine-MP versions before 5.44.2 fail to properly validate multiple ResourcePackClientResponsePacket packets with STATUS_COMPLETED status during resource pack handling. Malicious clients can send batches of these packets to repeatedly trigger pre-spawn progression, creating duplicate Player objects and amplifying memory consumption and network traffic.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-10
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
pocketmine mp to 5.44.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-837 The product requires that an actor should only be able to perform an action once, or to have only one unique action, but the product does not enforce or improperly enforces this restriction.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-86198 is a vulnerability in PocketMine-MP versions before 5.44.2 where the server fails to validate multiple ResourcePackClientResponsePacket packets with STATUS_COMPLETED status during resource pack handling. Malicious clients can send batches of these packets to repeatedly trigger pre-spawn progression, creating duplicate Player objects and increasing memory consumption and network traffic.

Detection Guidance

Monitor for unusual spikes in memory usage or network traffic during player login, particularly when resource packs are involved. Check server logs for multiple Player object creations from the same client session. Use network monitoring tools to detect repeated ResourcePackClientResponsePacket packets with STATUS_COMPLETED status.

Impact Analysis

This vulnerability can lead to a Denial of Service (DoS) attack by consuming excessive server resources. It increases memory usage due to duplicate Player objects and amplifies network traffic from duplicated large packets like AvailableCommandsPacket and CreativeContentPacket. Servers running vulnerable versions may experience performance degradation or crashes.

Compliance Impact

This vulnerability primarily causes a denial-of-service condition by consuming excessive server resources through duplicate Player object creation and amplified network traffic. It does not directly involve unauthorized data access, disclosure, or processing of personal data, which are key concerns under GDPR or HIPAA. The impact is limited to service availability and performance degradation rather than compliance violations related to data protection or privacy.

Mitigation Strategies

Upgrade PocketMine-MP to version 5.44.2 or later. Implement plugins that add custom PacketHandler classes to reject extra ResourcePackClientResponsePacket packets. Temporarily restrict access to the server until the update is applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86198. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart